Hackers can use credit bureaus to dox nearly anyone in America
404media.co
404media.co
However, once you've got it set up, it's very easy to freeze and unfreeze them. Just keep all the URLs, usernames, and passwords in a secure note somewhere, and any time you need to apply for credit, unfreeze them for a day or a week.
I used to have all sorts of identity theft problems (people taking out credit in my name) but freezing my credit has solved it.
Experian: https://www.experian.com/freeze/center.html
TransUnion: https://www.transunion.com/credit-freeze
Equifax: https://www.equifax.com/personal/credit-report-services/cred...
I truly hate these companies but holding my nose and going through the process was worthwhile and I'd recommend it to anyone.
If someone has your information, they can open a credit card under your name and max it out. Or even more common, they’ll get a car loan under your name. Since loans are furnished at the end of the day, they’ll often get 2 or 3 car loans in the same day.
The federal government requires that all three major bureaus (Experian, Equifax, TransUnion) provide you one credit report each per year, for free. You can request it here, the official source for these mandated free reports:
I had a difficult time getting loans to go to college many years ago. Come to find out my credit was through the floor due to all 3 agencies misattributing dozens of pages of bad loans to me starting when I was only a toddler. The middle initials & socials were 1 character off each, but it all still went to my name.
Unfortunately I didn't have the knowledge to freeze my credit when I was 3 years old - my fault, I should have known I would later suffer the consequences of my inaction.
-
We need a financial revolution (which is what OWS was all about -- and you know how they responded to that - especially in SFO.... "people are mad at the FED!, so must remove all planter boxes in front of the SF FED and install giant granite bollards and update our lifting stop gate at the entrance - and we have to get our fed workers to stop bragging about their $30,000 a month bonuses loudly on BART (yes this is an actual thing)
Issue isn’t if you have debt or not. Credit rating agencies start tracking very early, and what they’ll track for you is basically “no data/low credit score.”
That doesn’t mean you’re not in the system, or more importantly - doesn’t mean qn attacker can’t take out debt in your name.
A freeze is the only thing that stops this for you and your kids. I hate that it works this way but such is life.
Why not? Do you ever anticipate getting a mortgage? If yes, then you probably should be.
But credit scores are used for apartment rentals, and even employment.
This is false.
Millenials are trailing previous generations a little, but > 50% of them now own homes:
https://rentalhousingjournal.com/more-than-50-percent-of-mil...
So yeah, 10 years ago, very, very few millenials owned a home. But that was true for 23 year old boomers too.
https://www.forbes.com/sites/katherinehamilton/2023/04/21/ge...
Millennials own less homes than boomers did at their age. Though based upon the data Gen Z is possibly turning things around.
"Most US millennials finally own homes – and it’s not thanks to their parents"
https://www.theguardian.com/us-news/2023/aug/17/millennial-h...
Even the trailer parks aren't safe, as the companies buy them from the owners, evict all the tenants living in their own houses, and then develop the land into more unaffordable HOA clone mega houses, luxury apartments, or McMansions. Near where I live six of the eight trailer parks have disappeared in the last four years and have been turned into two separate campgrounds, a car wash, a dirt parking lot waiting to be redeveloped, a warehouse, and a new luxury senior apartment complex, with intent to redevelop the others into retail or housing shortly. There's been a spike in homelessness because the people living in these trailer homes couldn't afford to move their houses and didn't have anywhere left to go even if they could.
1. just ignore it, on the basis that the statistical data collected by many private organizations and the federal government say that it is incorrect.
2. as much as I hate quoting Bezos, he does have a good line about how, if anecdotes and data don't align, there's probably something wrong with the way the data is being measured and/or collected.
3. Accept that the data is correct, and that this sort of anecdotal reporting is also correct, but represents conditions that were also the case for previous generations yet somehow never became part of the zeitgeist.
I don't know which to choose. Maybe there are others.
I have a friend that works for one, and he's making a lot of money.
They come in, overbid, pay cash, and frequently spiff the agents (in a legal way).
Then they gut the place, and turn it into a pretty decent rental.
If you don't think these rental investment corporations are a problem, then I won't gainsay that. I just have some local IRL experience in the matter, and have seen it discussed.
I'm not in a debate. I made an offhand comment, which was not unique to me (it has been bandied about in popular culture for quite some time), you called it "false," in a fairly harsh manner, and I didn't attack back, because I like to behave myself, here.
If my offhand comment offended you, then I am sincerely sorry, and you have my apology, but it won't change the way I think or interact, and I'll likely offend again. I'm a decent person, and don't mean to offend, but I also have the approach I have, and some people find it offensive. I'm not sure why, because no one ever takes the time to explain. They just attack. I've learned not to attack back, and make my best guess at what their problem was. Given that data (my guess), I may (or may not) choose to modify my approach in future interactions.
In the aggregate, I yam what I yam, and some folks like it, and some folks don’t. Seems most folks find me easy to get along with.
No worries. It's all good. Have a great day!
You made a remark about millenial home ownership that, according to data collected by the relevant agencies, doesn't appear to be correct.
I just pointed out that millenial home ownership is only a little behind the age-adjusted levels for the last 4 "generations".
I think this is important - if the data is correct, then it's essentially a myth that millenials have no access to home ownership, and there's a certain kind of psycho-social danger to this idea being believed (particularly among millenials).
It is of course possible that the data is incorrect, or misleading, and I'm interested in that possibility, because the "story" about millenials and home ownership is widespread, and perhaps we should be alert to the idea that the data is not representing reality correctly.
Then you mentioned corporate residential real estate investment, which I certainly agree is a problem, but that seems orthogonal to the basic question of whether or not millenials do or do not own housing at roughly the same level as prior generations. I wondered if you saw some specific reason to mention it. If it were true that they do not, then certainly corporate RE investment could be a part of the reason. But it appears that in broad terms, they do, and so although it would be nice to end corporate RE investment somehow, it doesn't seem to be a particularly large problem.
I only take on debt I can immediately pay off (ie. credit card debt), but it still is important to demonstrate to creditors.
In addition, in the US these files are used for other purposes than taking out a loan, for example renting an apartment, for some jobs, etc.
I recommend building up a credit history even if you don't need it now. You might later. There are plenty of articles on the web about how to start, basically getting a credit card (perhaps secured) and slowly building up your credit.
I am lucky enough to be a cash buyer. I tried to rent a house for a year a few months ago but my credit rating was not good enough. I have a couple of credit cards which I pay off every month (so good, my credit utilization is low) but by the rating companys' POV there wasn't enough to go on: not enough accounts, and no accounts apart from the CCs: no mortgage, no car payments etc. The fact that I'm a homeowner doesn't appear in the report.
The victims of fraud in these cases are the banks, not you.
You still have your identity. The banks/creditors gave their money (not yours) to a criminal through their own neglect.
It's an unconscionable fantasy that you as an individual are the victim in these situations when you had no involvement whatsoever.
Laws need to be updated to reflect this reality. Banks will continue to act haphazardly so long as they are allowed to pass the bill for their own carelessness onto innocent people.
Awareness should be spread by disavowing the entire "identity theft" deceit any time it comes up in a public forum.
Highly relevant Mitchell and Webb radio skit:
There are plenty of things wrong with the current credit identity system, the name of identity theft is either not one of them at all or near the bottom of the list.
This is exactly the fantasy that we need to dispel, not rationalize.
Nobody steals your identity. You always have your identity, and nobody else ever does. Your identity is not the few pieces of trivia a criminal can easily discover about you.
The criminal never takes or has your identity. The bank is simply neglecting to correctly identify someone.
> steals that identity to abuse it
Criminals are not abusing your identity, they are abusing the banks' careless failure to correctly identify people.
> to abuse it and leave you with the baggage
The criminal is not leaving you with the baggage, the bank is. They use willfully inept processes, because they have tricked you into believing you should bear the responsibility for the consequences of their own hubris.
It's the latter that's being stolen. It's a crime against both you and your friends and creditors.
If you still disagree please try to make an argument without mentioning banks. Identity theft covers a lot more than banking fraud so the explanation shouldn't explain how you want the term to be changed to something which focuses solely on banks.
The processes in place do suck. That has nothing to do with the name of the crime though.
Someone who steals my passwords can impersonate me, they can not become me. Someone who tricks people into thinking they are me is still not me. An account is not an identity.
My online accounts are not me, and I am not my online accounts.
"1a: the distinguishing character or personality of an individual
2: the condition of being the same with something described or asserted
3a: sameness of essential or generic character in different instances"
Or the Cambridge dictionary:
"a person's name and other facts about who they are:"
Of course, you're always welcome to intentionally pick the incorrect context (going back to Merriam-Webster):
"4: an equation that is satisfied for all values of the symbols"
And just as easily rant the name of the crime has nothing to do with math so it needs to be renamed.
How this is interpreted is the primary problem that needs to be solved in order to legislate the issue, and from the interpretations you're supporting, it seems you're firmly on the side of the parties failing to identify fraudsters correctly, versus the innocent individuals.
As I've stated I'm in favor of the individuals. When doing so, I like to stick to factual and logical reasons why instead of insist the root of the problem is the chosen definition of "identity" does not match my preferred one. The root of the problem is the current process for dealing with identity theft is more burdensome than it needs to be on individuals. If you change the name it's still too burdensome because, outside of you, everyone already interprets "identity" to mean what it should in this case. That the process is bad is not proof the interpretation of the phrase is bad and needs to be fixed, it's proof the process is bad and needs to be fixed.
Just because someone disagrees with one component of your stance does not mean they automatically agree with all opposing positions that followed from it.
The victim of impersonation isn't held accountable for the action of the criminal, particularly with banks. That's precisely what identity theft laws protect. I'm in favor of making that process even easier for the victim wherever possible but changing the name is not that.
I don't think it's possible to avoid mentioning the banks. They are the ones committing the harm against you.
They are a stand-in for numerous other institutions who abuse you. You can take the name "bank" to mean any organization who is defrauded, and then abuses you to obtain repayment for that fraud.
I think it's important to recognize that this is a two-step process. The middle-man in this procedure is crucial, because they are the ones with a lot of power to use the legal system against you. If they were somebody other than a bank or other significant corporation, you'd be able to say, "No, I'm not the John Smith you gave money to. Go away and find that person." The imbalance makes it necessary to define the argument in terms of banks and similar institutions.
Claiming identity theft is precisely the process to notify the bank (or others) they cannot legally abuse you to get repayment for that fraud or you are not responsible for those crimes or whatever occured on your behalf. Under identity theft laws they are responsible for the loss due to fraud, not you. The same as credit card companies. The legal system is used but as much by you saying "I didn't buy that house, clear my records and eat the losses" as by the bank initially saying "this person didn't pay their loan". To not involve the legal system by both parties just opens up an even worse can of worms of fraud.
One thing I do agree on is that anything that can reasonably be done to make the process easier on the victim of identity theft should be as the process is too hard on them right now. Probably more fines to most middlemen to increase the cost further beyond their losses. I just don't think changing the name of the crime has anything to do with that kind of improvement.
This is actually a great example.
If you impersonate me in an e-mail and talk someone into sending a thousand dollars they owed me into some strange account, a reasonable victim isn't going to come to me and say "we're square now, because I paid that fraudster's account what I owed you."
Instead they should admit they made a mistake in assuming it was me based on suspiciously inadequate information and pursue the fraudster if they want their money back.
It is bank fraud and imitation with the intent to abuse the reputation of the person imitated. It should be illegal to imitate you when it negatively hurts you. It’s illegal to imitate police and doctors etc because it uses their reputations for fraudulent means. This is the same thing.
Banks are the financially defrauded victims in this situation, but the victims are also individuals because banks passed the reputational risk of fraud to the customers. If your credit score is hurt and you need to hire lawyers to fix it or you get denied for a mortgage (or just a good rate), you’ve experienced tangible harm.
Banks know they experience harm here. They plan for it. It’s baked into the prices and financial statements. Read the essays by Patrick McKenzie, he’ll argue that fraud is intentionally tolerated. They know that the consumer won’t be expected pay once the fraud is discovered. That’s not their goal, and they’re not being deceitful here.
You can argue if this system is overall good or bad, but it almost certainly has led to cheaper credit for everyone. Outsourcing credit worthiness to a magic national number (or 3) is cheaper than every credit union assessing risk themselves, with less knowledge.
In that case I am not a victim of the fraudster, I am a victim of the bank.
The banks do not have sufficient incentive to improve their identification methods, so long as we tolerate the concept that we bear any responsibility for a transaction that involves only themselves and a fraudster who knows the answers to a few trivia questions about me.
You’re not the victim of people who merely believe the lies and start to avoid you.
To me that was akin to being ostracized because your reputation was ruined by an impersonation.
On the contrary, they stand to risk 100% of the loaned money. What more could be at risk. Also the fair credit reporting act has pretty strict requirements for what a bank or credit agency should do when you’ve told them the debt is fraudulent, returning you to whole eventual.
What would be required to fix false identity frauds? Is that more or less tolerable for society than X% of people dealing with a stolen identity. What about people who have some problematic history (ran away from home, prior homeless, etc)? How would strict requirements impact them?
Really I guess my question. Oxygen_crisis, why do you believe identity theft is actually a problem that needs solving?
I think the argument is that the hurt is generated by the bank. Why isn't it the bank's responsibility to have their shit together and not do that?
Two big problems are:
1. If you happen to be one of the victims of the fraud, it hurts! Sometimes a lot! A lot more than it hurts the bank.
2. If you don't like the level of (in)security that the banks have chosen, what other options do you have? Right now I don't know, I think maybe Bitcoin is your best bet?
Because nobody can take out a fraudulent loan in bitcoin? Well.. that’s problem accurate.
I’m just not sure how is bitcoin even the tiniest bit relevant in this case?
That is, after all, what an “identity provider” actually provides.
Giving up ownership of our own identities led to very harmful results.
I kind of feel like banks are fans of one mister Dewey Crowe, "The anus is upon you" to protect your data. (https://www.imdb.com/title/tt1489428/characters/nm0380632?re...)
It took me months to prove that I wasa childless, 20-something dork in bay area...
nightmare - but any "credit" agency is scum
My nephew is now 20. When he was 5 we gifted him some cash in a savings account (to teach him about money stuff). We were immediately served notice that he was overdue on two mortgages. It took three years to get that straightened out (and find out that his ss# was already compromised).
What a mess. What kind of an agency would see the ss#for a literal child and just think, yep, this is fine.
I used to get my free credit report every year, but I stopped, which I'm sure is exactly what these scumbags want.
IME AnnualCreditReport.com was easy-to-use and never sends ads. It sounds like you were tricked into using something else. If you genuinely had an issue with AnnualCreditReport.com (unlikely), please do tell the FTC: https://consumer.ftc.gov/articles/free-credit-reports
Like, name one thing they actually do right. Literally anything. I challenge anyone who reads this to name a single bad thing that would happen if all these leech companies got Thanos-snapped out of the universe tomorrow.
We might have worse actors or arbitrary decisions or more expensive loans. Or, why not, all three!
So that was 15 years ago when these mortgages were taken out in his name? Placing it between 2007 and 2008.
That's basically right at the inflection point when the housing market had gotten out of control and started crashing down. This was caused because anyone could get a mortgage, regardless of whether they could afford it or who they were. The banks were accused of doing zero due diligence. In some cases no income verification, no identity verification, no job verification, etc.. You could take a mortgage out in your dogs name, and also apparently a 5 year old's name too.
I like to think that the system is better now, but that's probably a fantasy.
I have a very common name and some guy 20-30 years older than me had past due child support. I also have no kids. This was my first house purchase so I was completely ignorant of the process. What blew my mind is that before verifying whether or not that was me, they informed the sellers of it. I forget the process I went through to prove it wasn't me, I probably just showed them the guys age vs mine or something. That was wild though, like, the sellers could've just cancelled the sale right there if they didn't want to sell to a supposedly deadbeat dad. I couldn't believe they informed the sellers.
Buying a house is awful. Telling someone all of my finances and everything else when I already have an approved mortgage. Ugh. I did have a worse experience SELLING that house though, if you can imagine.
I think the lesson is when bad stuff happens you really don't want to be in the small minority of people who it is happening to. Once it's happening to everyone then the problem actually gets solved.
But then she was charged in the United States with offences including trademark infringement, and was told to pay damages of $US1.2 million ($1.8 million).
Her 'bogo-debt' can still be sold for cents on the dollar to local (Australian) collecters who might haress her, future vacations to US STeates and Territories are now ill advised, etc.So, give it time, when you least expect it, they will take 60 days to validate something about your account before allowing you to unfreeze it.
I had to deal fraudsters getting cell phones and also electricity to their apartment.
Setting a freeze up here solved it.
Seems to be an Equifax product.
It’s maddening that these companies give out service with wrong variations of my name and no ID but then want me to jump through hours of hoops to get it removed from collections.
Luckily I got it all resolved prior to rates shooting up so I was able to refi at all time low rates or this would have cost me a lot of money.
> A. Yes. NCTUE provides information to companies that provide consumers with pre-approved offers of credit. If you would like to Opt-Out and exclude NCTUE information about you from being used in lists provided to companies that make pre-approved offers of credit (as provided in the Fair Credit Reporting Act), you may call us toll free at 1-888-327-4376.
> You may also submit your request via mail to NCTUE at the address below. Please include your name, address, Social Security number and date of birth in your request.
... well that is infuriating.
Specifically:
1. Would it prevent any future occurrences?
2. Would it do anything to help with the leaks that have already occurred?
And none of the 3 allow MFA via something else than text/email.
Honest question, is sarcasm dead?
It falls under this case.
First, we notice the comment isn't an actual question, as there is nothing to actually be answered. This is a clear indication that its usage is therefore that of rhetoric. This is likely why they didn't respond, as there was nothing informative you could say unless you are significantly updating the premise which is being mocked.
Second, the diction and pattern of the sentence matches a commonly user sarcastic pattern of "wait, you're saying x but y?!" and the only thing missing is a surprised pikachu gif. It even does this at an abstracted level as it emphasizes the arbitrariness of the entity requesting the information. The pattern is up there with "I have a modest proposal" and I am having difficulties in even coming up with a more prominent pattern. There are several prominent memes built off of this.
Third, it involves additional flare to indicate a mocking of the obviousness of the claim made by the article which is summed by the parent. The comment is quite pejorative, with a clear disdain for the lack of accountability of the credit agencies.
As far as sarcastic comments go, this is about as blatant as one can get. Even my sarcastic addendum ("Is sarcasm dead?") is less obvious than the comment. Similarly the sarcasm you are employing is far less obvious. But none necessitate vocal inflections. I think your detector is defunct and you may wish to take it in for repairs or an upgrade.
I also disagree with your interpretation of when sarcasm works and I would suggest a different strategy. Your strategy will have a high false positive rate and teach you to misidentify sarcasm rather than learn to identify it. If a comment appears reactionary and condescending without a abundantly clear question to answer, either assume sarcasm or bad faith. In the latter case, one should not engage as you're only encouraging hostility. Simply downvote and move on. If you are wrong, you have just downvoted a sarcastic comment (which may not be adding too much to the conversation, as is the case here), which also sends a signal to the user that they need to work on their sarcasm or save it for other forums. You can take a middle case and hedge by saying "I think this is sarcasm, but if not..." This also goes with a different strategy of not responding if you don't have much to contribute. If you don't have a clear question to answer then the only reasonable responses are to ignore or ask for clarification, least you just create more noise. Internet conversations are well known to degrade easily and quickly.
We also should mention satire, as it is often employed. Satire's foundation is that of an alternative interpretation. The simple metric here is "would a reasonable person state this?" If there is any doubt to this, I suggest reading this document which describes the definition of satire while also making heavy use of it[0].
I mention that my addendum employs sarcasm, through exaggeration, but there is some real question to it, as lately I have seen severe identification even with the use of "modest proposals." Language itself is compression and if one is to take a literal interpretation of everything then you will be unable to accurately communicate and are likely to frequently enrage and annoy others. Due to the compressive nature, you will always be required to "read between the lines" otherwise even this sentence would be uninterpretable.
[0] https://www.supremecourt.gov/DocketPDF/22/22-293/242292/2022...
>The simple metric here is "would a reasonable person state this?"
You're saying there's universal agreement over the set of statements that are considered reasonable? Check out /r/PoesLaw.
Oops, I mean: Yes, because there's universal agreement over the set of statements that are considered reasonable.
Oh, and in a parallel thread, a error I'm sure you would never make /s:
Certainly not
That is quite divorced from what I wrote given that the model I presented is dependent upon accounting for modes of failure.
> Oh, and in a parallel thread, a error I'm sure you would never make /s
Quite the irony give littlestymaar is following a similar model as I am.
You noticed. My answer got 11 upvotes so far, so I think it was far from obvious without a careful reading, which I did not give it.
> This is a clear indication that its usage is therefore that of rhetoric.
Rhetoric is the art of writing or speaking effectively. It does not mean 'a questions which does not require an answer', which is a type of rhetorical device, but certainly not 'rhetoric'. I wouldn't bother mentioning this except you started the lecturing so I am proceeding in kind.
> This is likely why they didn't respond, as there was nothing informative you could say unless you are significantly updating the premise which is being mocked.
I don't try to ascertain the motives of people's non-responses. Guessing one option out of infinity seems like a losing game if you do it consistently.
> Second, the diction and pattern of the sentence matches a commonly user sarcastic pattern of "wait, you're saying x but y?!"
Sorry that I am not as up to date on meme phrasing as you are. Or maybe you are retrofitting a pattern after you already established it?
> As far as sarcastic comments go, this is about as blatant as one can get.
After re-reading it carefully, you may be correct.
> Even my sarcastic addendum ("Is sarcasm dead?") is less obvious than the comment.
You wrote 'honest question'. That is not sarcasm, not even a little bit. If you intended it to be, then I will absolutely call you a liar for using that terminology because some things should be taken literally and 'an honest question' is one of them. Like the 'biohazard' sign, it should never be used improperly, and if you are trying to press it into use as a non-literal phrasing, then I call you out and ask you to cease and desist.
> Similarly the sarcasm you are employing is far less obvious.
I have employed zero sarcasm in any of this correspondense. Perhaps your meter is faulty?
> I also disagree with your interpretation of when sarcasm works and I would suggest a different strategy.
Cool. I don't care.
> Language itself is compression and if one is to take a literal interpretation of everything then you will be unable to accurately communicate and are likely to frequently enrage and annoy others. Due to the compressive nature, you will always be required to "read between the lines" otherwise even this sentence would be uninterpretable.
And we must also account for non-perfect readings. The compressive nature of language means you are not reading every letter and every word all the time, you are fitting patterns and using previous experience to match them to correlations. This is an imperfect process. If your writing style cannot account for misreadings then I argue that you are doing it wrong.
Your pandering lecture has been noted and discarded.
TLOxp is the latest version of the game-changing technology that ushered in the science of data fusion
Who Uses TLOxp
Collections
TLOxp for Legal Professionals
General Counsel
TLOxp for Licensed Investigators
Financial Services
TLOxp for Insurance
Corporate Risk
Investigative Reporters
TLOxp for Law Enforcement
State, Local, and Federal Government
Asset Recovery and RepossessionIt's good to google yourself a couple times/year and file a request for those sites to remove you. Most of them do it fairly quickly.
It's unfortunate, but useful if keeping your info off these sites is important for safety/security. We're advocating for the CFPB to tighten regulation so this isn't such a challenge for people (and companies).
If interested in the technical challenges of scaling this, we're also hiring.
The amount of time/effort/rage that goes into dealing with a stolen identity makes paying for this a no-brainer.
Was there something that diminutives these claims?
In practice, I agree with your conclusion as the likely course of action.
We only even have SSL because no governments needed to be convinced to approve of it, and the list of operating system and browser vendors is so short that it became possible to essentially self-organize a set of generally-trusted root certificates.
Re govt distrust, not uniformly. As my older leftist friends remind me they grew up in a time were they thought anything was possible for their government to do, with enough protest they could get the civil rights act, the voting act, the infrastructure spending , etc with all their dreams on the horizon. Then a few people got a little too loud about ending poverty and other more ""radical"" progressive stuff and got killed for it. But it is possible, we've just been beat down for 50 years by neoliberal austerity politics.
Very interesting stuff re SSL. Any book recommendations you might have on the history of stuff like that? How security standards manifested and became adopted? from https to aes to pgp I vaguely know about all these things but would love to read more. I thoroughly enjoyed chip wars and master switch and stuff in that vein.
As for books, I wish I did have a recommendation but haven't read anything matching that description.
Can you imagine trying to get a loan and discovering that your identity has been cancelled and someone else has take it over now?
This is categorically false.
I've had transunion hand my entire credit report over to hackers who had nothing but public information, and transunion absolutely do not give a shit.
Now let's see if they care.
Transunion can't do shit about some Belarusian teenager stealing your identity any more than anybody can indict them for deploying ransomware on government networks. The framework for prosecution of international cybercrime does not exist.
Domestically, Transunion absolutely will shut down access to data furnishers who do not vet employees, in cases where an employee is bored and looking up their exes and random celebrities. It is a violation of the FCRA and subjects the bureau and the furnisher to fines. The bored employee scenario usually just results in termination but if there are other factors at play like identity theft/fraud, law enforcement absolutely gets involved.
This rogue employee scenario is the mechanic I'm guessing is being exploited here, only it seems crowdsourced to obfuscate attribution (so one person isn't making hundreds of fraudulent requests that gets them noticed).
This stuff happens at Equifax all the time too. People are always trying to look up Donald Trump, athletes and rappers in misguided attempts to see how much money they have or where they live. (Celebs have taken to getting around this by buying properties in relatives' names.)
They can but they don't. There being no framework for prosecution doesn't mean it's impossible to not hand out data to anybody that asks with minimal info provided.
I'm not sure what makes you think that, given you don't know any of the details involved.
In my case, TransUnion received credit checks for me with dates of birth 1 Jan, 2 Jan, 3 Jan, 4 Jan and so on until they hit upon my date of birth, then a credit account was opened that same day, then later in the day a third party credit monitoring agency accessed my credit report and they were allowed to pass 'knowledge based authentication' using their knowledge of that credit account.
I am completely sure TransUnion could have detected and foiled this incredibly obvious attack. I'm also completely sure they could have identified other victims of the same attackers and informed them, but they chose not to.
It's entirely possible that nobody at TransUnion knows how to achieve this given the state of their databases' and/or staff. For example, maybe their system was set up before constraints were a thing and they stopped development once it started printing money, so the only person "working" on it does light maintenance as a portion of their other duties.
The criminal made a false request for credit report. TU released the credit history without confirming ID. The bank relied on that credit report to extend credit.
The problem is, as a whole, ruining the credit of a few thousand people/year (and making them jump through hoops to regain their ID) is less costly than clamping down. TU absolutely contributes to the problem; they just have no incentive to fix it.
The notion that the fault would completely be on a "Belarusian teenager stealing your identity" and no responsibility whatsoever on people organising a system of massive private data collection in the first place, and then not even able to keep such data secure, is ludicrous. And even when you know that privacy invasion is attempted all the time you don't reach the conclusion that at the very least better securing the data would be needed, that task I'm not sure can be done by any "Belarusian teenager" - and that task has de-facto not be done by whoever is collecting and maintaining the private data that has leaked and is still leaking.
No they wouldn't. GDPR enforcement is severely lacking and the regulators tasked with enforcing it are either incompetent or corrupt.
I'm sure they would respond to a subpoena if you were willing to work with an attorney
They're not saying anything about how much they care about or follow-up on confirmation.
Ive walked into Commercial Real Estate brokerages where every single broker had a license to a credit bureau - with many of the junior brokers using it daily to look up real estate owners to call their mobile phones.
Obviously TLO knows theres no way a huge chunk of the CRE brokerage industry should be in their product on a daily basis if they were actually using a GLBA compliant use case... and they look the other way and find a way to monetize.
You really dont need to go digging in some dark corner of the internet to obtain this information... you can walk in through the front door
- Credit bureaus
Always call back on a number you look up, not one that they give you.
If the described scam happened, in should have required a simultaneous fault in the phone system. Or more likley, the scammer played a recorded sound of a disconnect+dialtone, which could tricker the target into dialing.
Someone pulled a trick where they took advantage of this. Had a friend call and keep the line open. Then claim that you have the entire phone book memorized. To prove it, ask someone to name a random name, punch in 7 digits and hand it off to the person who named it. They ask for the name and your friend says "yes that's me" (or "they're not home now if the gender mismatches).
This brings up one of those cultural things: ever noticed how in movies and TV shows from the 80s and 90s, if the caller hung up, the person called immediately got a dial tone?
It's a trope that prop wranglers, set designers, and writers picked up because the telephone company around Los Angeles (Pacific Bell) had switches that would reset the line state for the destionation back to "ready for call", which meant dial tone, when the origin side disconnected. If the destination side disconnected, the origin would only be disconnected after approximately 20 seconds.
Almost all other exchanges would put the destination--after the origin disconnects--into an off-hook-but-not-ready and then, after 10 or so seconds, play the "if you'd like to make a call, please hang up and try again" recording, then Special Information Tones, then a rapid busy.
Yet because the service in and around LA is what a lot of people in the TV and movie business experienced, it is what got baked into those productions.
I was a rather violent sleeper when I was young and would occasionally knock the phone off the hook while sleeping. Then I woke up to the fairly loud rapid busy sound. Hadn't thought about that a while.
Related to what some other commenters pointed out…
- The delay did seem to get longer when call-waiting became avaliable in an area.
- Sometimes, right after pressing your own hook and then releasing it, I could not dial; I had to wait a couple seconds.
- I never used a system where you could hang up and have time to run to another extension, but I may have known a couple people who claimed they could? If so, I probably dismissed it as "weird".
- My direct experiences were with various regions of just three Bells, so another commenter's remarks about LA/PacBell were interesting.
Thanks, everybody, for jogging my memory a bit.
This may have something to do with service offerings such as call-waiting and 3-way, which depend on detecting a "flash" signal.
I'd say anyone who is involved in anything outside of work probably has to answer phone calls.
Sometimes I notice the screen when someone calls, otherwise I call back when I next notice the phone, usually within an hour. If they're busy then, I just send a message instead.
I can't remember the last time I got a legitimate phone call except from work. It's been several years at the very least.
Thankfully, their CID is "Unknown/Unknown" and my spamblock sends it direct to voicemail.
Everyone is vulnerable to what this article is about
Then you confirm the scammer got good info.
Lenders already require independent verification of income and (for mortgages) monthly expenses.
The rest of the information that’s in your report and that is used to compute your credit score seems to be there to force people to get credit cards and to perpetuate systemic racism.
Articles like this read to a hacker like an article that door locks aren't secure.
This sounds very much like trusting a fox to guard the henhouse. When do they then do with the submitted personal information? Why should we trust that they will behave ethically with it? What happens if, and when, they have a data breach?
They have no incentive to behave incorrectly as all their business is based on trust.
https://help.joindeleteme.com/hc/en-us/articles/817118498523...
Then nobody knows. "What if?" works for litterally anything anywhere and nobody can respond to all of them, so I’m not sure what you’re expecting here.
If you want to be horrified, use a different email address for each service. I have a domain that I configured to forward to me, so for example if I got a loan through Hacker News Home Loans, I'd give them email "hackernewshomeloans@example.com" . Doesn't work for everything, but it is a good eye opener.
IIWM I think the benefits outweigh the cons of dropping the monitoring, but others may have different situations/priorities.
Consumer Reports also provides a free service called Permission Slip [1] that auto-submits opt-out requests for a variety of retailers/services as well as data brokers.
It is difficult to tell how effective these services are, but if nothing else, I’d prefer to minimize my footprint as much as possible. I don’t think this does much to help with the credit bureaus, though.
We desperately need real privacy laws with teeth.
- [0] https://www.optery.com/
forcing users to install apps, which can harvest much more personal data, seems sketchy to me, especially for a service that's supposed to understand that the user doesn't want that
I haven’t combed through the privacy policy on their website, but the way I see it, I’m not worse off by sharing a few bits of data with CR, and as far as I can tell, they’re not doing obviously nefarious things.
And offer a deleteme-like service with broad coverage and an affordable rate for removals and monitoring. We received a grant from YC for our work in 2019.
Basically, these companies will build profiles on anyone whose information gets reported to them, even if those profiles do not include a credit score.
Some banks will run a credit report from other agencies while opening too, but if you don't ask for or refuse any credit cards offered, you should have an empty report from them, once everything falls off.
But if you don't want to have a credit profile, then you can't use credit.
So instead of blindly trusting your credit score as the measure of your ability to repay a loan, a human looks at your situation - income, other debts, etc, and makes a judgement call. It's more paperwork and slower, but it definitely exists.
What really sucks is you can't practice good hygiene and preemptively update your SSN periodically. You have to wait until your identity is stolen first.
This used to be true, including in my state (Washington), but as of the last few years, I believe all states upon renewal of licenses now give you a non-deterministic license number.
Other than SSN, I don't find most of the information listed very concerning. Addresses, phone numbers, emails are semi-public anyways, considering that you hand them out anytime you make a purchase online. I'm not sure what bad stuff you can do with a drivers license id. Date of birth/relatives seems like something that can be sourced from public records (eg. voter roll). I'd prefer it if there weren't a telegram bot that dispenses all this for $15, but it's not exactly super privileged either.
...
"“Of all the entities that are the root cause of this data, “the credit bureaus are number one,” Shavell added. “They are the ones that should be subject to the strictest compliance and ultimately be held to a higher privacy standard by the federal government and by state governments than they are being,” he said."
TLDR: People are using social engineering attacks to gain access to data brokers' tools that tap credit bureaus' profiles of everyone. There are no incentives for the companies in this supply chain to perform adequate due diligence before granting access to the data.
This isn't a "bug", it's a "feature" to these companies' profit models. It's maybe a bug in the American system that so much of this data is in the hands of for-profit companies running a race-to-the-bottom auction on it.
Even to get the attention of a credit bureau you’ve to be their paid customer. A new loan in your name which didn’t even turn up in your dream? They helpfully tell you to contact the org that issued the loan. A card that’s not yours? Nope, not your problem. You can’t even tell them to delete your data altogether even if you’re fine working zero credit history.
Even to get your own data that they got without your informed consent you’ve pay!
There seem to be no venue! And suddenly one day I realise there’s yet another credit bureau and they have all my data! Amazing!
Their infra even feels so sketchy that you kinda know it can be hacked the moment someone tries.
As for freezing as some suggest, unfreezing is even worse. Besides it just doesn’t protect in case of data breach in any shape or form.
This is one field where I hope government regulates deep and hard into their collective bottom.
I'm amazed that the quote from a politician is the most even handed substantive part of this article. The rest of the article is essentially scaremongering a misguided narrative around "criminals" gaining access to surveillance databases, when the real problem is the uncontrollable and unaccountable surveillance databases existing in the first place. The US desperately needs a port of the GDPR to give us data subjects the rights to control and prevent dossiers being kept on us.
If a lender claims you borrowed money, and they cannot conclusively prove it was you, it should be their problem and their problem alone.
The fact that you have to prove you did not borrow money because a lender says your social security number was inputted into a form is a travesty.
In the form of government issued IDs and lately some governments even provide something digital.
The US government doesn't provide that.
No ID is required for domestic travel, even at big airports. Just be pleasant and explain that you misplaced it. I have misplaced ID several times, and only once I signed a piece of paper which roughly said that I am I because I say so.
They checkpoint all the thoroughfares near Mexico and I reminded my Spanish fiancée to carry her passport as we traveled domestically, and I was completely correct.
Law enforcement usually has ways of checking ID by radio/computer, so it may be a short stop, but still.
> On May 7, 2025, U.S. travelers must be REAL ID compliant to board domestic flights and access certain federal facilities.
Source: https://www.dhs.gov/real-id
Normally, I'd have had my backup travel ID/credit card/cash kit but, hey, this was a last minute couple night trip so I went light.
Figured that was that. But as it turned out really wasn't a major issue much to my surprise.
What was an issue was getting checked into the hotel I had been able to find for the event near the airport (Travelodge). I even had a photo company security badge, credit cards, etc. Eventually they let me, with great reluctance pay cash, which fortunately fleabag was cheap enough that my withdrawal limit covered. Thought I was going to have to call SV friends and find somewhere to sleep--or at least pay some ridiculous amount for the last room at some hotel where I belonged to their loyalty program. But TSA was actually not a real issue.
Said DHS policy is not infringing on your right to travel. You can still hire a private jet or fly yourself. The airline companies will just simply refuse to fly you, which they have the right to do.
What?
It's the REAL ID Act of 2005. 8 USC 1101. It's absolutely a law. (Also 49 USC 30301).
That isn't true:
> What Happens If You Don’t Register a Birth?
> By law, newborns must be registered within 10 days of their birth.
> In terms of legality, not registering the birth of a child is a violation of the law and a punishable crime. Depending on the state, the parents may be fined, charged with imprisonment, or have to face other legal consequences.
The US is actually insane about how little identification they require from residents and also not great about how expensive it can be to acquire certain forms of ID.
I'm curious how one obtains a US passport without a birth certificate or SSN.
(But yes, issuance of a passport is "optional").
Really helpful to have birth listed in a couple church public registers.
For baby passport, basically the parents attest to the child being born as American along with "hey look at this public record". And a SSN is apparently never required and State Dept should probably not being relying on a tax agency number. I mistakenly transposed and messed up the digits for the SSN box ten years ago and the passport arrived. So they didn't even do a lookup on it.
There are administrative rules all over the 50 States. Most don't apply to typical Americans but nobody knows that or they don't care because 'merica#1.
Oof, this absolutely reeks of sovereign citizen bullshit.
How to obtain a US passport with neither a SSN nor a birth certificate is apparently left as an exercise for the reader...
Leading with Washington, where I reside and work as a healthcare provider...
RCW 70.58A.100 (https://app.leg.wa.gov/rcw/default.aspx?cite=70.58A&full=tru...)
Specifically subsection 5:
> For an unattended live birth not reported under subsection (4) of this section, a report of live birth and an affidavit stating the facts of the birth must be filed with the department within ten calendar days of the live birth.
(whereby unattended means 'with no healthcare provider, midwife, or facility representative present or applicable'.)
(For bonus, RCW 70.58A.120 captures "delayed reporting of a live birth" and the "establishing of facts" around the birth.)
> How would they know for home birth
I was going to offer the comparison to driving, where "they" don't know you're driving without a license until there is some form of or need for government interaction. But I fear this will lead to some comment about traveling versus driving.
> and would they arrest the baby?
This is fatuous. "Depending on the state, the parents may be fined, charged with imprisonment, or have to face other legal consequences." (emphasis mine).
If I had a wife, I would ensure that she had all the rights and privileges of being my wife, and not have to jump through some ridiculous hoops made of red tape because some Sovereign Citizen told us it was optional to go see the JoP.
The only one you can't really dodge is a birth certificate.
The bank/lender/etc is the victim here. But somehow I have to take the fall. Well, next time they should ask me before lending money to "me".
> The bank/lender/etc is the victim here.
Actually you are the victim: you are a victim of the bank/lender/etc and they should be liable to compensate you with punitive damages for your any negative consequences to you.
If the bank or lender considers this unfair, let them try to recoup the cost of compensating you by suing the alleged fraudster who they claim "stole your identity" — but not before they compensate you first.
You are the victim of libel by the banks & credit agencies. They're the victims of fraud by the person(s) they lent the money to. There's no need (other than to protect the banks & credit agencies) to bundle both crimes together, call them "identity theft", and blame it on the individual victim!
But after a quick Google right now, it looks like they're just random private companies that get to do whatever they want because they have such strong established relationships with our major financial institutions.
CCPA was in the right direction, but AFAICT it explicitly carved out exemptions for credit bureaus.
We need to tighten the screws on these businesses; the only way we’ll see improvement here is if we hold them liable for damages and breaches. Right now they have very little incentive to care for this data, and all the incentive to try and monetize it as much as possible.
Still, people rarely consider the very valuable service they provide: without them, credit would be much more expensive in this country, or not offered at all. Want to see what a world without credit bureaus looks like? Go to a 3rd world country where everything is paid for in cash. This is not a good thing - it doesn't mean that everyone in these 3rd world countries are great savers while those in the first world live beyond their means. In means these 3rd world countries don't have institutions that can help to ensure trust between lenders and borrowers. As distasteful as it may feel sometimes, credit bureaus help ensure that trust by giving histories of the likelihood of someone's ability to repay a loan.
Again, to emphasize, this is not to say there are myriad problems with the way credit bureaus are currently run. It is saying the the primary service they provide (credit histories for individuals) is a good thing for society.
Other than that, the only other information a lender will use to decide whether to grant me a loan and under which conditions will be information that they will ask me to provide, such as age, proof of employment situation, and my last 3 payslips.
Absolutely, there are significant differences, and some are quite similar to us (Canada and the UK) others differ more significantly (France and Spain). But they all essentially have ways to record any black marks from your payment history and use that to determine your credit worthiness for new loan applications.
This is exactly what I meant in my first paragraph - yes, it's absolutely the case that the US implementation has tons of problems, and I think it's fine to say these should be public or quasi-public entities (e.g. only the the country's central bank has this info, like in France), but in general, all of these countries use some sort of analogous system to credit bureaus to determine your relative risk profile.
For example, I can go to the website of my county’s registrar and pull up the formation and renewal documentation of my LLC with just a last name.
I don’t think you can effectively hide ownership of property without a shell corporation. The Corporate Transparency Act passed in 2021 requires you to provide ownership records to the treasury but I believe that ownership of the corporation can stay anonymous to the general public.
If you're just trying to keep yourself off the Internet, just change your name to John Smith or Michael Jackson.
Although a trust is different from a corporation in many ways, they're similar in that they are both legal entities distinct from the people involved (and can both have their own tax ID numbers, also distinct from those people). They're primarily created for estate planning purposes, but public records will typically show only the name of the trust, not the people who live there.
Also, things like scores and rankings to get a loan/mortgage are not what I ever experienced. The procedure basically is, you take your last 3 salary slips and shop a few banks. You take the one with the lowest rent. Done. After all, you sign a document that states that the bank might sell your property if you do not pay off (for quite some months)
Or do I see it wrong?
Not sure if there's a telegram bot for that yet :D
Let's use math to obsolete FICO and shut down these parasites.
I suppose email and SSN are yikes inducing but after a decade of having my email sold to the political parties, I don't treasure it. SSN? Haven't we moved beyond SSN for security purposes?
From what I can tell, SSN is still somehow considered a form of identification in the US.
Edit: Commented too early.
Seems like there are basically no exceptions when it comes to banking.
That depends on your megabank. KYC and what staff will do over the phone is about relationships. I get things done over the phone at local credit unions and even mid-size regional banks. Banking and identity regulations allow a lot to happen, and your personal relationships make a difference.
The back offices of mega-banks generally prevent personal service. Choose a different banker.
Yes you can opt out even with credit cards, and you can also do it for minor children in 5 easy steps: 1 clone your trust document 2 IRS.com and get TIN for trust 3 open trust savings account at bank 4 put funds in account 5 get the bank's 'secured credit card' offer in which they lock the funds
If you quibble that a secured credit card is not a real credit card, then just get the debit card.
Unlisted numbers have been a white pages paid feature for a very long time. Very similar incentives in both directions compared to these headers, I’m sure. (Yellow pages were pay for inclusion, iirc.)
But it's more than you cherry-picked anyway:
> The file included the names and birth years of their relatives. It listed the target’s mobile phone numbers and provider, as well as personal email addresses. Finally, the file contained information from their drivers’ license, including its unique identification number.
Plus 'sometimes' Social Security Number as you said.
No, the banks haven't, which means you haven't, bucko.
Of course, this would completely change the risk model banks operate under and fundamentally reshape commerce as we know it. Thanks would become hypersensitive, all business would be conducted in person, banks would reserve the right to tie up your money for years if you couldn't prove who you were (think getting your Google account unlocked when Google suspects fraud, except now it's your money in the bank down the street...).
SSN is voluntary. If parents would stop opting-in their babies into this data scheme, Americans could grow up without these numbers.
After ominous threats about 'must choose name for baby' my wife and I left the hospital with our baby. Health insurer sent new member card with name 'baby girl' which worked great for all the follow-ups. And nobody from big government forced me to apply for SSN. We did get a passport (SSN on that application is optional) and travelled internationally before the first birthday.
Most of this nonsense data collection is voluntary. More and more in life I say "No thank you" and move on. Many Americans get a warm blanket feeling by putting their children into voluntary data schemes.
"Voluntary" but required to live like a normal human being isn't very "voluntary" in reality.
Get a job without an SSN.
Passport works great for ID all around, because it does not require SSN and does not have home address.
Many things, like TSA (Soviet era) checkpoints don't actually require ID. People seemingly prefer to act like cattle and show IDs everywhere and voluntarily consent to full body scans. Then people complain that their bits of privacy got leaked. Of course it leaked, and you voluntarily consented.
But you, you're walking the walk. Asking the hard questions and accepting the consequences. There is only one way to make things change.
Don't let any little pedants tell you "how your daughter is going to grow up", either. Or that they somehow know how she'll feel about you.
FWIW: my kids have SSN's and that is just as dangerous as what you've chose.
When you get/renew passports, leave the SSN box blank. It will become second nature to ignore these data requests.
Or have you already resolved to believe that person is your "some people"?
Are you absolutely sure that people who had real concerns about their privacy and safety allowed their phone number and address to be published in the book? Also, it was the White Pages, btw.
Ah yes, biometrics, the password that you can't change and you leave behind everywhere you go and on everything you touch.
Cloning a fingerprint is trivial. They're not secure.
You know what's really trivial? Buying a fake ID.
What chumps, just use https://freepeoplesearch.com
Ya it has ads but out of all the hundreds of "free" sites it has actually the most amount of free information.
> Sorry, you have been blocked
> You are unable to access truepeoplesearch.com
> Why have I been blocked?
> This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.
Edit: Name and state.